Command Injection Vulnerability in Renovate by RenovateBot
CVE-2026-76233

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76233?

Versions of Renovate from 39.53.0 and earlier are susceptible to a command injection vulnerability via the gleam manager. This issue arises from the inadequate sanitization of the depName parameter, which is incorporated without safeguards into gleam deps update commands. An attacker with repository write access can exploit this vulnerability by designing malicious gleam.toml files, thereby gaining the ability to execute arbitrary commands on the system that hosts Renovate.

Affected Version(s)

renovate 39.53.0 < 40.33.0

renovate 40.33.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

astellingwerf
.